1. 14 Apr, 2015 1 commit
  2. 07 Apr, 2015 1 commit
  3. 11 Dec, 2013 1 commit
  4. 04 Mar, 2011 1 commit
  5. 10 Jan, 2011 1 commit
  6. 15 Jan, 2009 1 commit
    • Jarod Neuner's avatar
      TLS Subject Checking in tport · 7b637c59
      Jarod Neuner authored
      sofia-sip/tport.h:
      * tport_delivered_from_subjects() returns type (su_strlst_t const *)
      * Export tport_subject_search()
      
      sofia-sip/tport_tag.h + tport_tag.c:
      * Remove TPTAG_TLS_VERIFY_PEER()
        - Depreciated.  Use TPTAG_TLS_VERIFY_POLICY instead.
        - Binary Compatibility is preserved.
      * Add TPTAG_TLS_VERIFY_POLICY()
        - tport can verify incoming and/or outgoing connections, using:
          1) Certificate Signatures only - or -
          2) Certificate Signatures and Certificate Subjects
      * Add TPTAG_TLS_VERIFY_DEPTH()
        - Restrict certificate chain verification to a set length.
      * Add TPTAG_TLS_VERIFY_DATE()
        - Disable notBefore/notAfter checking (application: embedded devices)
      * Add TPTAG_TLS_VERIFY_SUBJECTS()
        - Incoming connections must present client certificates with subjects
          that match an item in this list.
        - Intended Use: Proxy Authentication
      * Replaced TPTAG_TRUSTED() with TPTAG_X509_SUBJECT()
        - Commented out for future use.
        - Intended Use: SIP User Identities in Server Certificates.
      * Add appropriate doxygen documentation.
      
      tport.c
      * Add tport_subject_search()
        - Subject can be a hostname, IP Address, or a URI.
        - Valid subject examples include:
            example.com
            alice@example.com
            sip:alice@example.com
            sips:alice@example.com
      * tport_by_addrinfo() matches tpn_canon against the subject list
          of reusable TLS connections.
      
      tport_tls.h:
      * Add tls_init_secondary()
      * Remove tls_init_slave() & tls_init_client()
      
      tport_tls.c:
      * tls_verify_cb() supports TPTAG_TLS_VERIFY_DATE()
      * tls_post_connection_check() verifies certificate subjects.
      * tls_init_secondary()
        - Replaces tls_init_slave(), tls_init_client(), and tls_clone().
      
      tport_type_tls.c:
      * Removed erroneous reference to tport_tls_deliver()
      * Fix a memory leak caused by duplicate calls to tls_clone().
      * Populate the (tport_t *)->tp_subjects field with peer certificate data for
        new secondary connections.
      
      darcs-hash:20090115155045-2152f-aaec406d8e5dbf146949d4d3cbc9f56e201cba46.gz
      7b637c59
  7. 16 Dec, 2008 1 commit
    • Jarod Neuner's avatar
      Early TLS Handshake and Verification · 4af68bbd
      Jarod Neuner authored
      tport_type_tls.c:
      * tport_tls_accept():
        - Replaces tport_accept for incoming TLS connections.
      * tport_tls_connect():
        - Replaces tport_base_connect() for outgoing TLS connections.
      
      tport_tls.c:
      * tls_t now use a memory home instead of malloc.
      * removed tls_check_hosts()
      * tls_connect():
        - Replaces tport_base_connect for TLS connection setup.
        - Completes TLS handshake and verifies peer certificates.
        - Destroys suspect TLS connections before sending/receiving payload.
        - Populates a su_strlst_t with subjects from the peer certificate.
      
      tport.c:
      * tport_is_verified()
        - true if peer certificate validated successfully
      * tport_delivered_from_subjects()
        - Certificate subjects listed in the peer certificate.
      
      darcs-hash:20081216221937-2152f-3d6b74d411b57c22230e4840fca133da48c86368.gz
      4af68bbd
  8. 27 Nov, 2008 3 commits
  9. 26 Nov, 2008 1 commit
    • Paulo Pizarro paulo DOT pizarro AT gmail DOT com's avatar
      tport: new tag TPTAG_TLS_VERIFY_PEER · 0c8aac4a
      With this tag, the verification of certificates can be controlled:
      0: no verify certificates.
      1: on server mode, the certificate returned by client is checked and
         if fail the TLS/SSL handshake is immediately terminated.
      1: on client mode, the server certificate is verified and
         if fail the TLS/SSL handshake is immediately terminated.
      
      I added this tag, because I'd like that my application not connected to a
      server with a untrusted certificate.
      
      darcs-hash:20081126184231-daa5a-26fe2a4f958d2f931d3f7e9b31bc0426e7250a1f.gz
      0c8aac4a
  10. 27 Nov, 2007 1 commit
  11. 20 Sep, 2007 1 commit
  12. 17 Sep, 2007 1 commit
  13. 25 Jul, 2007 1 commit
  14. 01 Jun, 2007 1 commit
  15. 02 Feb, 2007 1 commit
  16. 22 Dec, 2006 2 commits
  17. 07 Dec, 2006 1 commit
  18. 05 Dec, 2006 2 commits
  19. 19 Oct, 2006 1 commit
  20. 26 Sep, 2006 1 commit
  21. 25 Sep, 2006 1 commit
  22. 20 Sep, 2006 2 commits
  23. 06 Sep, 2006 3 commits
  24. 12 May, 2006 1 commit
  25. 11 May, 2006 1 commit
    • Pekka Pessi's avatar
      Updated headers. · db555d76
      Pekka Pessi authored
      Added sofia-sip/ prefix to documentation entries referring to include files.
      
      Added SOFIAPUBFUN and SOFIAPUBVAR to files that missed them.
      
      Removed some deprecated functions and macros.
      
      darcs-hash:20060511143741-65a35-63e87cd71cb4839bf777488dcc66fbd0cb0a50a5.gz
      db555d76
  26. 03 May, 2006 1 commit
  27. 26 Apr, 2006 3 commits
  28. 11 Apr, 2006 1 commit
  29. 17 Apr, 2006 1 commit
    • Pekka Pessi's avatar
      Updated compression interface in tport. · 7aa0ca38
      Pekka Pessi authored
      Added tport_compressor_t type, tport_delivered_with_comp().
      Removed tpac_sigcomp_accept() and tport_delivered_using_udvm().
      
      darcs-hash:20060417233320-65a35-8a2571e39146a82f57e58d5e97c126392840c873.gz
      7aa0ca38
  30. 31 Mar, 2006 1 commit
    • Pekka Pessi's avatar
      Added stun server and compression plugins. · 31f5e43b
      Pekka Pessi authored
      Added TPORT_STUN_SERVER().
      Having stun server dependencies in <tport_stub_stun.c>.
      Moved sigcomp dependencies into <tport_stub_sigcomp.c>.
      
      darcs-hash:20060331154135-88462-90caca9b5511bfdae6efa5d609deee9d03841607.gz
      31f5e43b
  31. 27 Mar, 2006 1 commit